Error: RDP's requested extended connection timeout is out of range in PAM
search cancel

Error: RDP's requested extended connection timeout is out of range in PAM

book

Article ID: 447619

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

Users may experience failures when attempting to launch RDP or SSH sessions in Privileged Access Manager (PAM). This typically occurs when an administrator modifies global timeout settings while users are currently authenticated to the PAM client.

When launching an access session, the connection hangs or fails. The session logs contain the following error message:

RDP's requested extended connection timeout of #### is out of range. Minimum timeout is 30 maximum timeout is 60

Cause

This issue occurs when the "Connection Timeout" global setting is increased (e.g., from 20 minutes to 30 minutes) while users are already logged into the PAM Access page. The user's active session retains the old timeout value (20), which is now below the new global minimum (30), causing the connection request to be rejected as "out of range."

Resolution

To resolve this issue, perform the following steps:

  1. Log out of the Privileged Access Manager client entirely.
  2. Log back into the PAM client to refresh the session parameters with the updated global settings.
  3. Launch the RDP or SSH session again.

Note: Administrators should advise users to log out and log back in after making changes to Global Settings > Basic Settings to ensure all session parameters are synchronized.